KryptosAI/mcp-observatory

View on GitHub ↗

CI-native security testing for MCP servers. Attack simulation, schema drift detection, and health scoring before agents depend on them.

176 ★21 forksHTMLUpdated 18d ago

What you need to know

CI-native security and regression tool for MCP servers - catches broken tools, unsafe schemas, schema drift and security issues, and is itself an MCP server

Install

npx @kryptosai/mcp-observatory demo
Add CI with npx @kryptosai/mcp-observatory setup-ci --all

Usage

  • Scan all configured MCP servers with npx @kryptosai/mcp-observatory
  • Add as an MCP server with claude mcp add mcp-observatory -- npx -y @kryptosai/mcp-observatory serve

Key features

  • Attack simulation, schema drift detection and record/replay/verify workflows
  • Security scanning for shell injection surfaces and credential leakage
  • Health scoring 0-100 with verdicts and badges
  • SARIF and GitHub Code Scanning output plus PR comments
  • MCP server mode with 10 tools for AI agents
  • Command allowlist and path validation against prompt injection
  • CI setup that generates GitHub Actions workflows

Best for

Teams shipping custom MCP servers who need CI security, drift and health checks

Caveats

  • Servers requiring interactive OAuth need pre-authentication
  • Custom WebSocket transports are not supported
  • Production support through a paid pilot program
Platforms: Local · CIClients: Claude Code

Reviewed 2026-08-11

Topics

agent-securityai-agentai-securityai-supply-chainclicode-scanningdeveloper-toolsgithub-actiongithub-code-scanningmcpmcp-cimcp-securitymcp-servermcp-testingmodel-context-protocolregression-testingsarifschema-driftsecuritysupply-chain-security
Stars
176★
Forks
21
Language
HTML
License
MIT
Created
2026-03-19
Last push
2026-08-18